2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3933 | MEDIUM | 5.4 | 0.9% | Dec 12, 2022 | The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow... |
| CVE-2022-3930 | MEDIUM | 6.5 | 0.6% | Dec 12, 2022 | The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to chan... |
| CVE-2022-3919 | MEDIUM | 4.8 | 0.5% | Dec 12, 2022 | The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users s... |
| CVE-2022-3908 | MEDIUM | 6.1 | 0.9% | Dec 12, 2022 | The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2022-3906 | MEDIUM | 4.8 | 0.4% | Dec 12, 2022 | The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-3883 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not... |
| CVE-2022-3882 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not ... |
| CVE-2022-3881 | MEDIUM | 5.7 | 0.4% | Dec 12, 2022 | The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Lo... |
| CVE-2022-3880 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4... |
| CVE-2022-3879 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authori... |
| CVE-2022-3862 | MEDIUM | 4.8 | 0.5% | Dec 12, 2022 | The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which... |
| CVE-2022-3853 | MEDIUM | 5.4 | 0.2% | Dec 12, 2022 | Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a w... |
| CVE-2022-3609 | MEDIUM | 4.8 | 0.4% | Dec 12, 2022 | The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow... |
| CVE-2022-45956 | MEDIUM | 5.3 | 0.8% | Dec 12, 2022 | Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method... |
| CVE-2022-4421 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of t... |
| CVE-2022-45970 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board. |
| CVE-2022-44648 | MEDIUM | 5.5 | 0.7% | Dec 12, 2022 | An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to di... |
| CVE-2022-44647 | MEDIUM | 5.5 | 0.7% | Dec 12, 2022 | An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to di... |
| CVE-2022-44532 | MEDIUM | 6.5 | 0.7% | Dec 12, 2022 | An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Success... |
| CVE-2022-43518 | MEDIUM | 6.5 | 0.7% | Dec 12, 2022 | An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful explo... |
| CVE-2022-42446 | MEDIUM | 6.5 | 0.4% | Dec 12, 2022 | Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ab... |
| CVE-2022-42445 | MEDIUM | 4.9 | 0.5% | Dec 12, 2022 | HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to re... |
| CVE-2022-37930 | MEDIUM | 5.5 | 0.2% | Dec 12, 2022 | A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary ... |
| CVE-2022-37929 | MEDIUM | 5.5 | 0.1% | Dec 12, 2022 | Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble ... |
| CVE-2022-37928 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Fla... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now